02.11.2012 Views

Handover mechanisms in next generation heterogeneous wireless ...

Handover mechanisms in next generation heterogeneous wireless ...

Handover mechanisms in next generation heterogeneous wireless ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

PROXY BASED AUTHENTICATION LOCALISATION SCHEME FOR HANDOVER<br />

not be overheard by the sAN. The sAN forwards these session key renew credentials to<br />

the MH. If N m that is <strong>in</strong>cluded <strong>in</strong> the key renew response is valid, the MH generates<br />

another mobile nonce N m ' , and establishes the new session key PMK’ accord<strong>in</strong>g to<br />

Equation 6.7. The newly issued nonce N m ' will be delivered to the FAP as shown <strong>in</strong><br />

Figure 6.7. Based on the two new nonces N m ' and N p ' , the FAP can derive the<br />

correspond<strong>in</strong>g PMK’. Later on, the derived PMK’ is provided to the AN for updat<strong>in</strong>g<br />

the session key.<br />

E<br />

LAK<br />

( Nm<br />

|| Ns<br />

')<br />

ELAK<br />

( Nm<br />

')<br />

- 127 -<br />

E<br />

pa<br />

E<br />

{ ELAK<br />

( Nm<br />

|| Ns<br />

')}<br />

pa<br />

{ ELAK<br />

( Nm<br />

')}<br />

EK (PMK'<br />

)<br />

pa<br />

Figure 6.7 Session key renewal procedure <strong>in</strong>itiated by AN<br />

In this thesis, it is assumed that the communications between a MH and an AN are<br />

always protected by other l<strong>in</strong>k layer security <strong>mechanisms</strong>. For example, IEEE 802.11i<br />

[42] def<strong>in</strong>es how the PMK can be utilised to ensure a secure association with an access<br />

po<strong>in</strong>t.<br />

6.4 Security Analysis for the PBAL<br />

In the proposed PBAL scheme, the authentication authority is temporarily relayed to a<br />

third-party entity FAP when a mobile subscriber roams outside the territory of its home<br />

network. The FAP plays a similar role as the Visitor Location Register (VLR) of 3GPP<br />

<strong>in</strong> verify<strong>in</strong>g a mobile user’s identity us<strong>in</strong>g the home-supplied authentication vectors, as

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!